Today with the tremendous series of undocumented or poorly documented protocols how an incident responder on the network can can present the packet by capturing a binary executable file. The contents of such files can be parsed by conventional static and dynamic techniques. In many situations one can¿t detect even the binary file for analysis. So a new process of Protocol Reverse Engineering (PRE) leveraging multiple sources of information to accelerate incident response detection. It is a pseudo-formal survey of the tools, techniques, and methodologies that I've experienced or observed to be effective that is deliberately proscriptive, rather than prescriptive. It is not an exhaustive study, and only designed to cover common needs of analysts - particularly engaged in incident response.
Autorius: | Hemant Kumar Saini, Satpal Singh Kushwaha, |
Leidėjas: | LAP LAMBERT Academic Publishing |
Išleidimo metai: | 2014 |
Knygos puslapių skaičius: | 52 |
ISBN-10: | 3659627828 |
ISBN-13: | 9783659627828 |
Formatas: | Knyga minkštu viršeliu |
Kalba: | Anglų |
Žanras: | Databases / Data management |
Parašykite atsiliepimą apie „Protocol Discovery: A Reverse Engineering of Network Applications“